Well, Coldcard isn't open-source either. But unlike Ledger, Coldcard has a public and verifiable codebase.
Pardon me, but isn't verifiable codebase synonym to open-source? In the Github repository, you have everything needed to study the source code of the firmware. Why doesn't that count as open-source? Also, in
bitcoin.org it marks it as open-source, but I do notice it's the only place that it's called that way.
Electrum's tried and tested but sometimes it just fails and when it does it fails horribly, so take using Electrum with a massive hand of salt.
Bitcoin Core and Electrum are the two most tested and reviewed Bitcoin software. Where does it fail? Open up
an issue.